|
611
|
7.2 |
HIGH
Network
|
-
|
-
|
In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass
New
|
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-33392
|
2026-04-18 00:13 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
612
|
5.0 |
MEDIUM
Local
|
-
|
-
|
Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems from the lack of validation for applications access…
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-40002
|
2026-04-18 00:13 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
613
|
- |
|
-
|
-
|
Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals plaintext OAuth2 client secretDesktop client decodes the secret and uses the pl…
New
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2025-15622
|
2026-04-18 00:13 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
614
|
- |
|
-
|
-
|
Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud…
New
|
CWE-359 CWE-497
Exposure of Private Personal Information to an Unauthorized Actor Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2025-15623
|
2026-04-18 00:13 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
615
|
- |
|
-
|
-
|
Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server.
In a setup where OpenID is used as the primary method of authentication to authenticate to Sparx EA, P…
New
|
CWE-256
Plaintext Storage of a Password
|
CVE-2025-15624
|
2026-04-18 00:13 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
616
|
- |
|
-
|
-
|
Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases.
New
|
CWE-89 CWE-200
SQL Injection Information Exposure
|
CVE-2025-15625
|
2026-04-18 00:13 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
617
|
7.2 |
HIGH
Network
|
-
|
-
|
An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow a remote privileged attack…
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2026-40688
|
2026-04-18 00:12 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
618
|
2.4 |
LOW
Network
|
-
|
-
|
An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6.0 through 7.6.5, FortiNAC-F 7.4 all versions, FortiNAC-F 7.2 all versions may a…
Update
|
CWE-601
Open Redirect
|
CVE-2026-21741
|
2026-04-18 00:11 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
619
|
5.7 |
MEDIUM
Network
|
-
|
-
|
A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3…
Update
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-21742
|
2026-04-18 00:11 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
620
|
6.0 |
MEDIUM
Local
|
-
|
-
|
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all…
Update
|
CWE-22
Path Traversal
|
CVE-2025-68649
|
2026-04-18 00:11 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|